[BEFORE PUBLISHING — REPLACE EVERY BRACKETED PROVIDER NAME WITH THE ACTUAL VENDOR, ITS ENTITY NAME AND ITS LOCATION.]
A sub-processor page with placeholder names is worse than no page, because customers will ask and the gap becomes visible at exactly the wrong moment. The categories and the structure below are correct; the names must be real before this goes live.
Three commitments that apply to every entry on this page:
1. Every sub-processor is engaged under a written contract imposing obligations materially equivalent to those we owe you.
2. Caresoft remains fully liable to you for its sub-processors. "Our vendor did it" is not a defence we will offer.
3. We give 30 days' notice before a new sub-processor begins processing your data, and you may object.
Where we process personal data on your behalf, a sub-processor is a third party we engage that also processes that data — a hosting provider, a messaging gateway, a payment processor. Under the Digital Personal Data Protection Act, 2023 and the GDPR where it applies, you are entitled to know who they are.
A vendor is only a sub-processor if it can access your data. A supplier we buy laptops or accounting software from is not.
Before engaging any sub-processor we assess: security posture and certifications; where it processes and stores data; its own sub-processing chain; incident history and how it handled incidents; its contractual willingness to accept obligations equivalent to ours; and whether the function can reasonably be performed without it.
The last question is the one that keeps this list short. Every sub-processor is another party holding customer data and another link that can fail. We add one when the function genuinely requires it, not because a tool is convenient.
Used across products unless a product schedule says otherwise.
| Provider | Function | Data it can access | Location |
|---|---|---|---|
| [Hosting provider — entity name] | Application and database hosting, backups | Encrypted data at rest and in transit for the products it hosts | India — [region] |
| [Transactional email provider] | System email — account notices, reports, alerts | Recipient address and message content | [location] |
| [SMS gateway] | OTP and notification SMS | Mobile number and message text | India |
| [WhatsApp Business Solution Provider] | WhatsApp messaging where a product uses it | Mobile number and message text | [location] |
| [Payment gateway] | Subscription and customer payments | Payment details. Card data is held by the gateway, never by Caresoft | India |
| [Error monitoring provider] | Application error reporting | Stack traces and technical context. Configured to scrub personal data before transmission | [location] |
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, payments | Account data |
| [AI provider] | AI-assisted suggestions — only where AI features are enabled | The passage being checked. Contractually prohibited from training on it. Can be disabled entirely per organisation |
On-premise deployments have no sub-processors — nothing reaches Caresoft or any third party.
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, payments | Account and booking data |
| [Video conferencing providers] | Meeting links, where the Host connects one | Meeting details. Independent controllers once connected by the Host |
| [Calendar providers] | Free/busy and event creation, where the Host connects one | Calendar data. Google user data handled under Limited Use requirements |
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, payments | Imported accounting data, account data |
| [AI provider] | Prompt bar dashboards — only where AI is enabled | The prompt and relevant schema and figures. Prohibited from training on it. Can be disabled entirely |
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, payments | Content, schedules, proof of play |
| [CDN / media delivery] | Delivering creative to screens | Media files. No patient or queue data |
No audience measurement provider exists, because there is no audience measurement — no cameras, sensors or tracking.
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, SMS | Profiles, applications, messages |
| [Document storage / virus scanning] | Resume and certificate handling | Uploaded documents |
Employers who receive an application become independent controllers of their copy — they are not sub-processors.
| Provider | Function | Receives |
|---|---|---|
| Shared infrastructure (§3) | Hosting, email, SMS, payments | Partner and user data, opportunities |
For products processing health data, no sub-processor outside India is engaged for that data without the customer's prior written consent.
This applies to Caresoft HIS, MyOPD, ClaimX, Caresoft VMS, Caresoft eICU, Nirvaan and Manova.
| Product | Sub-processors | Note |
|---|---|---|
| MyOPD — clinic management | Hosting (India), SMS, WhatsApp BSP, email, payments | No AI provider. ABDM ecosystem participants are independent controllers, not sub-processors |
| ClaimX — cashless claims | Hosting (India), email | No AI provider. Payers and NHCX are independent controllers on receipt |
| Caresoft VMS — visitor management | Hosting (India), WhatsApp BSP for OTP, SMS | BSP receives number and OTP text only |
| Caresoft eICU — tele-ICU | Per the standalone eICU DPA | Clinical-safety obligations apply |
| Nirvaan — consultations | Hosting (India), [call bridging telecom provider], SMS, email, payments, [fulfilment partner and courier] | Call bridging receives numbers and duration, never consultation content. Courier receives delivery details only |
| Manova — behavioural health screening | Hosting (India), email, SMS | Screening responses never leave our infrastructure |
| OJSP Support — patient support programme | Caresoft as technology processor, hosting (India), SMS, email | OJSP Ayurved and Foods Private Limited is the Data Fiduciary |
Wherever an AI provider appears on this page, three things are always true:
1. Our contract prohibits them from using your data to train models.
2. The feature can be disabled entirely for your account, and the product works without it.
3. No AI provider processes health data in any Caresoft product without the customer's prior written consent.
| Product | AI used? | Disable? |
|---|---|---|
| Sahi | Yes, optional | Per organisation or department |
| Sales Sathi | Yes, optional | Per account |
| MyOPD | No | — |
| ClaimX | No | — |
| Nirvaan | No | — |
| Caresoft VMS | No | — |
| Screenify | No | — |
These support our operations. Most never touch customer data; where one can, it is listed as a sub-processor above.
| Tool | Can it access customer data? |
|---|---|
| [Support desk] | Yes — whatever a customer includes in a ticket. Treated as a sub-processor |
| [Internal email and collaboration] | Only if a customer emails us data. We discourage sending personal data by email |
| Source control, CI, project tracking | No. Production data is never present in these systems |
| Accounting and payroll | No customer personal data beyond billing contacts |
Please do not send us personal data in a support ticket — screenshots of patient records, exports containing customer lists, spreadsheets of employee data. Describe the problem and give us a reference; we can look it up under the access controls in the DPA. It keeps your data out of a ticketing system that was never designed to hold it.
Parties frequently assumed to be sub-processors that are not:
| Party | Why not |
|---|---|
| ABDM ecosystem participants | Independent controllers. They receive records on the patient's consent through ABDM, not on our instruction |
| Insurers, TPAs and NHCX (ClaimX) | Independent controllers on receipt. We transmit; we do not control what they then do |
| Employers receiving applications (CareHire) | Independent controllers of their copy |
| Calendar and conferencing providers a Host connects (Sloto) | Independent controllers, connected by the Host under their own terms |
| Practitioners on Nirvaan | Independent Data Fiduciaries for their own clinical records |
| Your own accounting software vendor (Sales Sathi) | No relationship with us at all |
| Resellers and implementation partners | Not given access to customer data unless the customer instructs it, in which case a written agreement is put in place first |
Where necessary for service continuity or security — a provider fails, suffers a breach, or ceases operating — we may engage a replacement without prior notice, and will inform you as soon as practicable with the reason. Your objection rights under §9 then apply from the date of that notice.
Subscribe to be notified of changes to this page. Enter an address at [[email protected]] or use the subscribe control on this page. We recommend a distribution list rather than an individual, so notices survive people changing roles.
Customers with a signed DPA are notified directly at their registered data protection contact whether or not they subscribe.
| Date | Change | Products affected | Notice given |
|---|---|---|---|
| [DD Mon YYYY] | Initial publication | All | — |
| Every addition, removal or change of a sub-processor is recorded here. This history is not edited or pruned. | |||
Sub-processor questions and objections: [[email protected]]
Security: [[email protected]]
Grievance Officer: [name], [[email protected]] — acknowledgement within 24 hours, resolution within 15 days
Caresoft Systems Private Limited, [registered office address], CIN [CIN]